PT-2026-24254 · Oneuptime · Oneuptime
Iconnnjka
·
Publicado
2026-03-10
·
Atualizado
2026-03-17
·
CVE-2026-30958
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OneUptime versions prior to 10.0.21
Description
OneUptime is a solution for monitoring and managing online services. A path traversal issue exists in the
/workflow/docs/:componentName API endpoint, allowing unauthenticated reading of arbitrary files from the server filesystem. The componentName route parameter is directly concatenated into a file path and passed to the res.sendFile() function within the orker/FeatureSet/Workflow/Index.ts file without any sanitization or authentication checks.Recommendations
Update to version 10.0.21 or later.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oneuptime